Issue #276
Monday · August 31, 2026
🥖 Palate Cleanser
After the IAM Roles Manager drama, some really nice folks from AWS finally reached out to chat. Turns out they do understand that rolling opposite-of-least-privilege is a bad idea but they're just hamstrung by product rollout sequencing. Not great, but also not the disaster I worried about. You've already seen some of what's coming but expect pretty dramatic changes in how people sign up and start interacting with AWS for the first time.
I think we have enough evidence now that AI is pretty good at escape rooms. Either the escape rooms need to get harder or we need to rethink sandboxing. Trail of Bits gave a cyber-tuned model SSH into a QEMU/KVM VM and told it to get out. It escaped three times, finishing with several 0-days it found itself after the host was rebuilt from latest upstream, while the researcher's main contribution was power-cycling the box every time the agent hardlocked the kernel.
Enjoy 4 chef's selections today instead of 3. I'm a rebel without a cause.
This issue is also available to share online. Got feedback? Tell us here.
📋 Chef's selections
AWSHound: An OpenSource AWS OpenGraph Collector
BloodHound turns Active Directory permissions into a graph, so finding a path to domain admin becomes a database query instead of a manual audit. People have been trying to bring this idea to AWS for years. dAWShund did it by asking AWS itself, one SimulatePrincipalPolicy call at a time, which is accurate but apparently noisy, and only sees identity and resource policies. AWSHound is an offline implementation that decides each edge locally, treating a permissions boundary as a ceiling and evaluating SCPs and RCPs. In one real run it turned more than 500 accounts into 10.5 million edges in about fifteen minutes of processing.
Data Exfiltration from Amazon Kiro via Prompt Injection
by Fergal Glynn
I feel like I've been writing about AI-assisted development tools doing crazy stuff every other week for months. Can't stop now. Aaron got Kiro to read an index.md planted in a workspace the victim opened, go hunting through the repo for a .env, and write what it found into the workspace's own kiroAgent.powersRecommendationUrl setting, at which point the IDE itself fetched the attacker's endpoint with an OPENAI_API_KEY in the query string. Amazon fixed it and paid a $40 Amazon merchandise gift certificate...
A Wildberries Architected Framework
by Chris Farris
In March, missiles took out two of the three availability zones in AWS's Middle East (UAE) region, and nearly six months later both me-central-1 and me-south-1 apparently still cannot reliably run customer workloads. Chris' point is that in Europe the targets would never be hard to find, because a facility pulling tens of megawatts needs a grid interconnection, shows up on any decent satellite pass, and, unlike in the US, goes through planning approval with a public objection period. Maybe it's time to factor geopolitics, not just latency, into how you pick your regions.
I lost my mind doing an AWS external access review
Doing an external access review in AWS really shouldn't be this hard but if you take 2-pizza to the extreme, this is what you get. In case you ever try to do it yourself, this post will either guide you through all the inconsistencies and edge cases, or help you realize it's a bad idea to try.
💸 Sponsor shoutout
Most code shipped today is AI-generated and the triage queue grew to match. Pleri AI works out which findings are actually exploitable and submits the fix. See the platform and get a free assessment.
🥗 AWS security blogs
- 📢 Amazon Aurora DSQL now supports foreign key constraints
- 📢 Amazon Cognito adds admin API operation to reset user TOTP configurations
- 📢 AWS Batch now supports Amazon ECS Managed Instances
- 📢 IAM Roles Anywhere now provides a Java plugin for the AWS SDK
- 📢 AWS Lambda functions now support full IAM resource-based policies
- SailPoint Agent Identity Security for AI agents on Amazon Bedrock AgentCore by Imaan Tariq
- Building Multi-Region Active-Active Architectures with CloudFront VPC origins and Advanced Routing by Hiroki Harigai
- Shared DNS views for multi-account environments with Amazon Route 53 Global Resolver by Aanchal Agrawal
- What HCLS security teams can do this quarter to close the execution gap by Adam Birnbaum
- Extend your data perimeter to the AWS Management Console with Private Access by Madhur Kulkarni
- Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK by Stephan Traub
- ICYMI: July 2026 @AWS Security by Rodolfo Brenes
- Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation by Nisha Kashyap
- Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS by Kevin Donohue
🍛 Reddit threads on r/aws
🤖 Dessert
Every machine-tracked change this week. Nobody else assembles this.
🧁 IAM permission changes
🍪 API changes
- Agents for Amazon Bedrock
- Amazon Bedrock AgentCore
- Amazon Cognito Identity Provider
- Amazon EC2 Container Service
- Amazon HealthLake
- Partner Central Selling API
- AWS CodeDeploy
- Amazon Cognito Identity Provider
- Amazon DataZone
- Amazon Elastic Compute Cloud
- Lambda MicroVMs
- Amazon CloudWatch Logs
- Amazon Relational Database Service
- AWS DevOps Agent Service
- Amazon Elastic Compute Cloud
- AWS License Manager User Subscriptions
- AWS Network Firewall
- Amazon SageMaker Service
- Auto Scaling
- AWS DevOps Agent Service
- Amazon Elastic Compute Cloud
- Amazon Elastic Kubernetes Service
- Amazon Elastic VMware Service
- IAM Toolbox (Preview)
- AWS IoT
- Amazon Connect Contact Lens
- Amazon Connect Service
- AWS Elemental Inference
- Managed Streaming for Kafka
- AWS Launch Wizard
- AWS Security Agent
- Timestream InfluxDB
🍹 IAM managed policy changes
- AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy
- AWSBackupServiceRolePolicyForRestores
- AWS_ConfigRole
- AWSConfigServiceRolePolicy
- SageMakerStudioProjectUserRolePolicy
- AWSServiceRolePolicyForWorkspacesInstances
- SageMakerStudioAdminIAMConsolePolicy
- AssuranceServiceRolePolicy
- AIDevOpsChannelAccessPolicy
- AWSAccountSettingsManagementRole
- SecretsManagerReadWrite
- AWSBatchServiceRole
- CloudWatchNetworkMonitorServiceRolePolicy
- SageMakerStudioProjectProvisioningRolePolicy
- AWSSupportPlansReadOnlyAccess
- AWSSupportPlansFullAccess
- AWSBackupServiceRolePolicyForS3Backup
☕ CloudFormation resource changes
No resource updates this week.
🎮 Amazon Linux vulnerabilities
- CVE-2026-42008: Dovecot trusted-proxy field injection spoofs auth
- CVE-2026-52687: Dovecot IMAP compression memory-exhaustion DoS
- CVE-2026-40018: Dovecot wrong MySQL multi-byte escaping
- CVE-2026-42392: Dovecot URLFETCH leaks uninitialised memory
- CVE-2026-33607: Dovecot IMAP LIST CPU-exhaustion DoS
- CVE-2026-82324: GIMP IFF/ILBM plugin bad HAM row validation
- CVE-2026-82327: libsolv .solv cache parsing flaw
- CVE-2026-38346: Firefox/Thunderbird FFmpeg integer overflow DoS
- CVE-2026-40019: Dovecot ManageSieve pre-auth infinite loop DoS
- CVE-2026-40205: Dovecot OAuth2 partial-scope auth bypass
- CVE-2026-80179: python-jwcrypto malformed JWE DoS
- CVE-2026-73208: Dovecot OAuth2 wrong-audience token accepted
- CVE-2026-33605: Dovecot ManageSieve pre-auth crash
- CVE-2026-80489: glibc charset conversion DoS
- CVE-2026-73209: Dovecot compressed data stack exhaustion crash
- CVE-2026-40203: Dovecot IMAP compression side channel
- CVE-2026-56854: Go x/crypto/ssh source-address restriction not enforced
- CVE-2026-42393: Dovecot doveadm secret comparison timing leak
- CVE-2026-27852: Dovecot huge header memory-exhaustion DoS
- CVE-2026-82343: GIMP PSD plugin bad channel-count validation
- CVE-2026-52681: Dovecot Sieve CPU accounting reset bypass
- CVE-2026-40017: Dovecot IMAP THREAD hash-collision DoS
- CVE-2026-42007: Dovecot Sieve editheader use-after-free
- CVE-2026-42391: Dovecot pre-auth IMAP ID resource exhaustion
- CVE-2026-33604: Dovecot crafted line ending bypasses relay checks
- CVE-2026-40014: Dovecot IMAP THREAD CPU-exhaustion DoS
- CVE-2026-33263: Dovecot submission-login epoll panic crash
- CVE-2026-82330: GIMP PVR plugin VQ decoder OOB access
- CVE-2026-33606: Dovecot mail content injects dsync commands
- CVE-2026-40204: Dovecot lda autocreate bypasses ACLs
- CVE-2026-42395: Dovecot NUL byte in proxy header crashes login
- CVE-2026-82328: GIMP ICO plugin bad palette-count validation
- CVE-2026-40015: Dovecot imap-hibernate out-of-bounds access
- CVE-2026-40013: Dovecot Sieve numeric literal OOB write
- CVE-2026-81934: Redis TLS pending-data use-after-free
- CVE-2026-78002: rsyslog RainerScript replace() heap overflow
- CVE-2026-81521: MongoDB Go Driver unescaped database name
- CVE-2026-81893: gdk-pixbuf crafted JPEG ICC profile flaw
- CVE-2026-5680: Undertow WebSocket permessage-deflate DoS
- CVE-2026-18374: glibc fopen ,ccs= empty string flaw
- CVE-2026-57171: Compliance-trestle path traversal
- CVE-2026-63676: libyaml backtracking exponential load DoS
- CVE-2026-77117: glibc SHIFT_JISX0213 conversion crash
- CVE-2026-19542: glibc tdelete out-of-bounds stack access
- CVE-2026-19499: glibc strfmon buffer overflow
- CVE-2026-79902: GIMP SFW plugin stack VLA overflow
- CVE-2026-57170: Compliance-trestle custom validator flaw
- CVE-2026-19953: perl URI IDNA skips Unicode normalisation
- CVE-2026-52776: Compliance-trestle URL validator bypass
- CVE-2026-75466: libjpeg-turbo PNG loader divide-by-zero
- CVE-2026-80158: Ansible ipa_getkeytab leaks bind password
- CVE-2026-77680: libsoup HTTP Range algorithmic complexity DoS
- CVE-2026-59184: OpenEXR crafted file memory flaw
- CVE-2026-63075: OpenSSL QUIC ACK-handling DoS
- CVE-2026-73180: Tomcat WebSocket session not expired
- CVE-2026-59183: OpenEXR crafted file out-of-bounds read
- CVE-2026-79783: rclone fails to mask setuid/setgid bits
- CVE-2026-65979: OpenEXR HTJ2K decoder flaw
- CVE-2026-59984: OpenEXR crafted file memory corruption
- CVE-2026-59985: OpenEXR crafted file memory corruption
- CVE-2026-16599: wget FTP OPIE challenge DoS
- CVE-2026-65182: Tomcat security constraint bypass
- CVE-2026-79776: rclone exposes pprof debug handler unauthenticated
- CVE-2026-79777: rclone RC API leaks Go stack traces
- CVE-2026-79775: rclone SquashFS parser DoS
- CVE-2026-68763: Tomcat HTTP/2 backlog allocation leak DoS
- CVE-2026-14457: OpenSSL raw public key handling flaw
- CVE-2026-68525: Tomcat FORM auth constraint bypass
- CVE-2026-79652: Keycloak JWT bearer grant authorisation flaw
- CVE-2026-79992: Emacs TRAMP crafted filename code execution
- CVE-2026-61555: OpenEXR crafted file memory flaw
- CVE-2026-55371: OpenEXR crafted file memory flaw
- CVE-2026-59186: OpenEXR crafted file out-of-bounds read
- CVE-2026-59187: OpenEXR crafted file memory corruption
- CVE-2026-79781: rclone serve s3 path traversal
- CVE-2026-79778: rclone WebDAV TUS nil dereference DoS
- CVE-2026-66422: Tomcat security-role-ref improper authorisation
- CVE-2026-54757: Compliance-trestle path traversal
- CVE-2026-80185: BlueZ SDP type confusion crashes bluetoothd
- CVE-2026-63076: OpenSSL CMP protection verification flaw
- CVE-2026-54874: OpenSSL DTLS future-epoch memory buffering DoS
- CVE-2026-80101: GIMP XWD plugin bad size validation
- CVE-2026-59981: OpenEXR crafted file memory flaw
- CVE-2026-68513: OpenEXR crafted file memory corruption
- CVE-2026-55373: OpenEXR crafted file memory flaw
- CVE-2026-59982: OpenEXR crafted file memory flaw
- CVE-2026-55059: OpenEXR crafted file out-of-bounds read
- CVE-2026-63073: OpenSSL CMP format string flaw
- CVE-2026-68515: OpenEXR crafted file memory corruption
- CVE-2026-79782: rclone leaks S3 token over HTTP redirect
- CVE-2026-79780: rclone leaks IAM tokens and SSE-C keys on redirect
- CVE-2026-68514: OpenEXR crafted file out-of-bounds read
- CVE-2026-62986: OpenEXR crafted file read flaw
- CVE-2026-65927: Tomcat rewrite valve off-by-one
- CVE-2026-78701: 389-ds-base SASL UNBIND flaw
- CVE-2026-39113: SQLite buffer overflow
- CVE-2026-54920: OpenEXR reachable assertion DoS
- CVE-2026-78322: file-roller long archive path flaw
- CVE-2026-15310: Python zip decompression memory exhaustion
- CVE-2026-63074: OpenSSL CMP extraCerts cache never expunged
- CVE-2026-65637: Tomcat incomplete fix for CVE-2026-32990
- CVE-2026-80186: BlueZ remote stack buffer overflow
- CVE-2026-52491: libtiff thumbnail RCE
- CVE-2026-68569: Tomcat authenticates users without credentials
- CVE-2026-65183: Tomcat unix socket TOCTOU race
- CVE-2026-79779: rclone replays auth headers over plaintext HTTP
- CVE-2026-59983: OpenEXR crafted file read flaw
- CVE-2026-59189: OpenEXRUtil crafted file flaw
- CVE-2026-18798: OpenSSL QUIC server double free
- CVE-2026-63072: OpenSSL CMS key-unwrap buffer overflow
- CVE-2026-65905: Tomcat DIGEST auth capture-replay bypass
- CVE-2026-52490: libtiff tiffcrop RCE
- CVE-2026-78367: rpmbuild tarball macro injection
- CVE-2026-76844: webpack-dev-middleware path traversal
- CVE-2026-77310: jackson-databind data-binding flaw
- CVE-2026-75803: OpenSSL missing AEAD tag check on finalize
- CVE-2026-68516: OpenEXR crafted file memory flaw
- CVE-2026-78465: GIMP PCX plugin allocation flaw on 32-bit
- CVE-2026-78323: JSS ignores NSS trust flags on CA certs
- CVE-2026-52492: libtiff rgb2ycbcr integer overflow
- CVE-2026-53532: OpenEXR crafted file memory flaw
- CVE-2026-78475: GIMP PIX plugin stack VLA overflow
- CVE-2026-76098: python-mistune nested token DoS
- CVE-2026-78376: WebKitGTK use-after-free memory corruption
- CVE-2026-19685: NetworkManager 802.1X CA path restriction
📺 AWS security bulletins
🚬 Security documentation changes
No changes this week.